Skip to content
Content type · 160 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 160 sort newestlargest fineoldest
RON 108,570 ANSPDCP (Romania) - Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Art. 32 Data Breaches Notification Obligation Security Aug 11, 2026
RON 523,900 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… Art. 25, 32 Security Data Breaches Notification Obligation Jul 29, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Personal Data Jul 17, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 Privacy Impact Assessment DPIA Data Breaches Jul 16, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Personal Data Accountability Jul 13, 2026
€1,198 Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software contained… Slovenia ·IP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
RON 26,172 ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that… Romania ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives Corrective Actions and Duty of Information Framework Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Human Resources Supervisory Authorities Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€6,600 Italian Garante: Employer's recording of locker opening and destruction of contents The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Garante per la protezione dei dati personali ·Art. 2, 4, 5 +2 Personal Data Legitimate Interest Integrity and Confidentiality Principle Jun 18, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Right of Access Security Jun 13, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Personal Data Controllers Direct Marketing Jun 2, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Healthcare May 28, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Processors Controllers May 25, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Controllers Personal Data Data Breaches May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Notification Obligation Security May 8, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Data Breaches Notification Obligation Processors Apr 13, 2026
Austrian DSB rules 360-degree feedback unlawful without specific works agreement The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department,… 2025-0.960.016 ·Austria ·Art. 6, 88 Legitimate Interest Personal Data Human Resources Mar 20, 2026
€150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Spain ·aepd ·Art. 5 Integrity and Confidentiality Principle Security Supervisory Authorities Mar 20, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Social Media Feb 11, 2026
€10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… SPAIN ·aepd ·Art. 32 Encryption Integrity and Confidentiality Principle Telecommunications Feb 3, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Personal Data Healthcare Jan 12, 2026
€60,000 ENDESA (energieleverancier): Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Processing NL Dec 30, 2025
€60,000 ENDESA (energy supplyer): Insufficient legal basis for data processing The complainant's bank account was charged by ENDESA, the beneficiary of which was a third party, who had been convicted under criminal law and imposed with a two-year restraining… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Dec 30, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Controllers Integrity and Confidentiality Principle Oct 9, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data May 19, 2025
€500,000 Handelskamer, Industrie, Dienstverlening en Transport van Spanje: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 14 Processors Processing Controllers NL Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Fairness & Transparency Processors Apr 15, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Apr 9, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Processing Integrity and Confidentiality Principle NL Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 28, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·azop ·Art. 13, 32, 33 +1 Integrity and Confidentiality Principle Health Data Healthcare Mar 24, 2025
€120,000 BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine against BEEDIGITAL AI, S.A.. A individual had lodged a complaint with the DPA against the controller because they had received advertising from… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Professional Secrecy Feb 11, 2025
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… Notification Obligation Data Breaches Integrity and Confidentiality Principle Dec 17, 2024
€160,000 ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.. A person had filed a complaint with the DPA because their ex-partner had been given… SPAIN ·aepd ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Insurance Jun 10, 2024
Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·APD/GBA Legitimate Interest Direct Marketing Marketing May 16, 2024
Belgian DPA settles with Mediafin: De Tijd cookie banner must add equal "refuse all" On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·APD/GBA Cookies Direct Marketing Consent Nov 24, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·aepd ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Social Media Oct 25, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC ·Unknown Fines Cookies Integrity and Confidentiality Principle Aug 2, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Insurance May 12, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Security May 12, 2023
€10,000 Informatica Alto Adige Spa: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Informatica Alto Adige Spa EUR 10,000. The municipality of Bolzano had reported a data protection breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 32 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Encryption Data Breaches Security Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Right of Access Mar 14, 2023