Skip to content
Content type · 94 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 94 sort newestlargest fineoldest
HRK 940,000 AZOP (Croatia) - Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Art. 15 Video Surveillance Right of Access Fines Aug 3, 2026
RON 523,900 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… Art. 25, 32 Security Data Breaches Notification Obligation Jul 29, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Controllers Right of Access Personal Data Jul 22, 2026
€90,000 AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right of Access Procedures Controllers Retention Period Jul 21, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Personal Data Right of Access Accuracy Jul 17, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Right of Access Security Jun 13, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Controllers Personal Data Direct Marketing Jun 2, 2026
EDPB - Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·Art. 4, 57, 60 +3 Supervisory Authorities Cookies Telecommunications May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Criminal Data Processing May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Fairness & Transparency May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Encryption Security Fines May 8, 2026
APD/GBA: Controller failed to provide copies of service sheets for GDPR access request The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained… 97/2026 ·Belgium ·Art. 12, 15 Right of Access Procedures Right of Access Accuracy May 6, 2026
SLOVENAKIË, DPB: Onvoldoende naleving van de rechten van betrokkenen. Slovaakse Autoriteit voor Gegevensbescherming. SLOVAKIA ·Slovak Data Protection Office ·Art. 15 Right of Access Procedures Right of Access Personal Data NL Dec 30, 2025
€15,000 Crowd Entertainment Limited: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Een boete van €15.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Right of Access Data Controller NL Dec 10, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Right of Access Dec 4, 2025
€3,000 Cucina di Fabio S.R.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Processing Marketing Personal Data NL Nov 26, 2025
€2,000 Whitedecor SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Processing Personal Data Data Controller NL Nov 10, 2025
€1,000 Bedrijf: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Data Controller NL Nov 7, 2025
€2,000 Bureau voor het innen van openstaande schulden S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Processing NL Oct 22, 2025
€1,000 Green.mec. s.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Personal Data Right of Access Data Controller NL Sep 25, 2025
€1,000 Giada FM S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 12, 15 Right of Access Data Controller Personal Data NL Sep 11, 2025
€1,000 Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Health Data Right of Access Procedures Healthcare NL Aug 5, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Personal Data Jul 11, 2025
€12,000 Data Diggers Market Research SRL: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van €12.000 - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Processing Personal Data Data Controller NL May 21, 2025
€2,000 Ziekenhuis Tirrenia S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Personal Data Healthcare Health Data NL Apr 29, 2025
€1,000 Xiting ROM SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Data Controller Personal Data NL Apr 28, 2025
€20,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 12 +4 Processing Personal Data Marketing NL Apr 22, 2025
€1,000 Office Nova Concept SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Right of Access Personal Data Right to Object NL Apr 14, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Health Data Personal Data Healthcare NL Apr 9, 2025
€4,000 CREMA GAMES, S.L.: Onvoldoende nakoming van de informatieverplichtingen. Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 15 Controllers Data Controller Personal Data NL Mar 28, 2025
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Right of Access Procedures Inspection Access Rights and Cooperation Obligations Fairness & Transparency Jul 2, 2024
FRANCE DPA: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine on a controller for not sufficiently respecting data subjects' rights (exercising the right of access to a medical file). CNIL ·Insufficient fulfilment of data subjects rights Right of Access Procedures Right of Access Inspection Access Rights and Cooperation Obligations Jun 5, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… Autoriteit Persoonsgegevens Social Media Fairness & Transparency Inspection Access Rights and Cooperation Obligations May 16, 2024
Belgian DPA: Political campaign email without consent violates GDPR and ePrivacy On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·APD/GBA Legitimate Interest Direct Marketing Marketing May 16, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Procedures Right of Access Healthcare Jan 31, 2024
€174,640 Black Tiger Belgium: Insufficient fulfilment of information obligations The Belgian DPA has imposed a fine of EUR 174,640 on Black Tiger Belgium. An individual had filed a complaint with the DPA due to the controller's failure to properly comply with… APD ·Art. 5, 6, 12 +5 ·Insufficient fulfilment of information obligations Storage Limitation Right of Access Right of Access Procedures Jan 16, 2024
€1.7M Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 1.7 million on Arbeids- og velferdsetaten, the Norwegian Labor and Welfare Administration (NAV). During its investigation, the DPA… NORWAY ·Datatilsynet ·Art. 5, 24, 25 +1 Security Right of Access Public Authority Nov 27, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Right of Access Nov 13, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Encryption Data Breaches Integrity and Confidentiality Principle Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Integrity and Confidentiality Principle Right of Access Mar 14, 2023
€1,600 Deca s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,600 on Deca s.r.l.. Employees had filed a complaint with the DPA because the controller had not complied with their requests for access… ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Mar 9, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Privacy by Design & Default Mar 6, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€15,000 A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined A&G Couriers Limited T/A Fastway Couriers (Ireland) EUR 15,000. During a changeover of its IT systems, the controller had suffered a cyberattack in… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Right of Access Privacy by Design & Default Dec 30, 2022
€2,000 Homeowners Association: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a homeowners' association. An individual who did cleaning work in the residential complex had filed a complaint with the DPA… SPAIN ·aepd ·Art. 6, 15 Personal Data Right of Access Controllers Dec 28, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Integrity and Confidentiality Principle Security Dec 9, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Integrity and Confidentiality Principle Security Nov 25, 2022
DKK 500,000 Datatilsynet (Denmark) - 2022-63-0003 A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Art. 5, 9, 24 +2 Data Breaches Security Integrity and Confidentiality Principle Oct 28, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Personal Data Right of Access Sep 22, 2022