Skip to content
Content type · 105 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 105 sort newestlargest fineoldest
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield Processing Agreement International Transfer Aug 25, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Supervisory Authorities Information Provision Modalities and Communication Methods Jul 3, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Child Consent Personal Data Right to Object Jul 3, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Transparency Personal Data May 12, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers International Transfer DPIA Dec 30, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·AEPD ·Art. 5 Controllers Processing Recipient Jun 20, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Personal Data May 15, 2025
€80,000 CALOGA: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 80,000 on CALOGA. The controller is a company obtaining data from data brokers to use those for marketing purposes. The DPA found multiple… FRANCE ·CNIL ·Art. 5, 6 Controllers Processing IP Address May 15, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… DPC ·Art. 13, 46 Processing Agreement International Transfer Personal Data May 2, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Retention Period Apr 15, 2025
€6.3M Poczta Polska SA (Polish Post): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 6.3 million on Poczta Polska SA (Polish Post) for the unlawful disclosure of personal data of over 30 million citizens from the PESEL… POLAND ·UODO ·Art. 6 Personal Data Processing Agreement International Transfer Mar 17, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Feb 25, 2025
APD/GBA · 131/2024 On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·Art. 4, 5, 6 Personal Data Supervisory Authorities Controllers Oct 11, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Identification Supervisory Authorities Processing Sep 12, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… AP Personal Data Privacy Shield International Transfer Jul 22, 2024
€1.3M Avanza Bank AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1.3 million on Avanza Bank AB. The controller had used so-called meta pixels on its website and app, which caused personal data such as… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 24, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Personal Data Anonymization Pseudonymization Apr 15, 2024
€1.2M CAIXABANK, S.A: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on CAIXABANK, S.A. A person filed a complaint with the DPA because they were asked to fill out a form with personal data. A clause on the form… SPAIN ·AEPD ·Art. 6 Consent Personal Data Security Apr 12, 2024
Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 International Transfer Controllers Legitimate Interest Mar 8, 2024
€10M Uber Technologies Inc. Uber B.V.: Insufficient fulfilment of information obligations The Dutch DPA has fined Uber Technologies Inc. and Uber B.V. EUR 10 million for failing to provide sufficient information about the storage period of European drivers' data and… THE NETHERLANDS ·AP ·Art. 12, 13 Personal Data International Transfer Supervisory Authorities Dec 11, 2023
€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Retention Period Processors Controllers Dec 6, 2023
€20,000 City of Kópavogur: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Retention Period Processors Controllers Dec 6, 2023
€16,600 Reykjanesbær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Retention Period Processors Controllers Dec 6, 2023
€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Retention Period Processors Controllers Dec 6, 2023
€13,300 City of Reykjavik: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 13,300 on the city of Reykjavik. The city had used the Google Education system in schools without sufficiently complying with data… ICELAND ·Persónuvernd ·Art. 5, 24, 28 Processors Controllers Supervisory Authorities Dec 6, 2023
€60,000 Limit Call S.r.l.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 60,000 on Limit Call S.r.l.s. for unauthorized telemarketing. The controller had acquired lists of personal data without checking the… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Consent Controllers Nov 30, 2023
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·AEPD ·Art. 5, 25, 32 Privacy by Design & Default Privacy by Default Privacy by Design Oct 26, 2023
€6.1M ENDESA ENERGÍA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has fined ENDESA ENERGÍA, S.A.U. EUR 6,1 million due to a security breach resulting in unauthorized access to its systems. The controller had informed the DPA that… SPAIN ·AEPD ·Art. 5, 32, 33 +2 Integrity and Confidentiality Principle Data Breaches Controllers Oct 25, 2023
€800,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined BANCO BILBAO VIZCAYA ARGENTARIA, S.A. EUR 800,000. A customer had lost her handbag, which also contained her bank card. The individual therefore… SPAIN ·AEPD ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 20, 2023
€1,040 Self Employed Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 1,040 on a self employed person. The accused's website did not comply with GDPR requirements for cookies, as it processed data before… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 5, 13 Personal Data Supervisory Authorities Consent Sep 26, 2023
€3,570 Legal Person: Insufficient legal basis for data processing The Czech DPA has imposed a fine of EUR 3,570 on a legal person. Following the complaint, the Office for personal data protection carried out an inspection of the accused's… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 13, 44 International Transfer Personal Data Supervisory Authorities Aug 1, 2023
€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€1M Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€4.9M Spotify: Insufficient fulfilment of data subjects rights The Swedish Data Protection Authority (DPA) has imposed a fine of EUR 4.9 million on the music streaming provider Spotify. The DPA had launched an investigation after receiving a… SWEDEN ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Personal Data Supervisory Authorities International Transfer Jun 12, 2023
€15,000 Thin Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Thin Srl. The authority took action following a complaint from a GP who alleged that the company had breached data protection… ITALY ·Garante ·Art. 5, 9, 13 Healthcare Personal Data International Transfer Jun 1, 2023
€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… DPC ·Art. 46 Processing Agreement International Transfer Supervision May 12, 2023
€200,000 GSMA LTD.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal… SPAIN ·AEPD ·Art. 35 DPIA Controllers Personal Data May 3, 2023
€300,000 Ediscom S.p.a.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Ediscom S.p.a.. The marketing company had collected data from 21 million individuals via various online portals in order to… ITALY ·Garante ·Art. 5, 6, 7 +3 Marketing International Transfer Supervisory Authorities Feb 23, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€700 Company: Insufficient fulfilment of information obligations The DPA of Luxembourg has imposed a fine of EUR 700 on a company that provides online services to citizens. During its investigation, the DPA found that the company had not… LUXEMBOURG ·CNPD (LU) ·Art. 12, 13 Personal Data International Transfer Controllers Dec 13, 2022
€400 Legal Person: Insufficient fulfilment of data subjects rights The Czech DPA has imposed a fine of EUR 400 on a legal person. The accused did not provide access to information about the purpose of the processing, the storage period, the… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 15 Personal Data Controllers Supervisory Authorities Nov 9, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD (PT) ·Art. 5, 9, 12 +5 Privacy Shield Controllers Processors Nov 2, 2022
2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Denmark ·Datatilsynet (DK) DPIA Controllers Prior Consultation
€2,000 SC Raiffeisen Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA. An individual had filed a complaint with the DPA for receiving text messages about money transfers to… ROMANIA ·ANSPDCP ·Art. 5 Personal Data Processing Insurance Sep 9, 2022